CVE-2026-29647
EUVD-2026-2396020.04.2026, 21:16
In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even when mstateen0.IMSIC is cleared, potentially enabling cross-context information leakage or disruption of interrupt handling.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.